To send a password over text message safely, don't type the password into the text. SMS isn't end-to-end encrypted, and copies sit on phones, synced devices, backups and carrier systems. Put the password in a self-destructing note, text the one-time link, and share any passcode by phone call or another app.
Key takeaways
- SMS isn't end-to-end encrypted, and a texted password lingers on phones, synced devices, backups and possibly carrier systems.
- Text a one-time link instead of the password, set to 1 view and a short time limit.
- Send the passcode through a different channel, such as a phone call.
- If you already texted a password, change it. Deleting the message isn't enough.
- For passwords you share long-term, a password manager is the better tool.
Is it safe to text a password?
Not really. Standard SMS was designed to carry short messages, not secrets. It isn't end-to-end encrypted, so the carrier's systems handle your message in readable form on its way to the other phone.
The bigger problem is what happens after delivery. A texted password doesn't vanish once the other person has typed it in. It sits in the thread, often for years.
Even standards bodies treat SMS with caution. NIST's digital identity guidelines class SMS as a restricted option for delivering one-time login codes, because of risks like SIM swaps and interception. If SMS is shaky for a six-digit code that expires in minutes, it's worse for a password that works until you change it.
Where does a texted password actually end up?
When you send a password via SMS, count the copies you've just made:
- Your phone and theirs. The message stays in both threads until someone deletes it, and most people never do.
- Lock screens. Notification previews can show the password to anyone glancing at a phone on a desk or kitchen counter.
- Linked devices. Texts often sync to a tablet or computer signed into the same account, including shared family devices.
- Cloud backups. Phone backups usually include messages, and that copy can outlive the phone itself.
- The carrier. Mobile networks route your messages and may keep records of them. How long varies by provider and country.
- A hijacked number. In a SIM swap scam, an attacker moves your number to their own SIM and starts receiving your texts.
Deleting the text on your side removes one copy out of several. That's why the safer move is to never put the password in the text at all.
How to send a password over text message the safe way
The fix is simple: text the link, not the password. You put the password in a one-time note that's destroyed after it's read, and the text only carries a link that soon stops working. However many copies of the text exist, they point to nothing.
Here's how to do it with SecureNotes. It's free and there's no account to set up.
- Paste the password into a new note. Go to SecureNotes and create a self-destructing note. Paste only what the person needs, such as the password and, if necessary, the username. Notes are text only, up to 10,000 characters.
- Choose when it self-destructs. For a password, pick 1 view and a short time limit such as 24 hours, whichever comes first. If they never open it, the link dies anyway.
- Add a passcode. It's optional, but worth it. Anyone who spots the link on a lock screen or a synced laptop still can't open the note without the passcode.
- Ask for a read notification if you want one. SecureNotes can email you when the note is opened, so you know it reached the right person.
- Create the note and copy the link. The note is encrypted with AES-256 using its own random key before it's stored.
- Text the link. Paste it into your message with a short explanation so the recipient knows it's really from you.
- Send the passcode another way. Call and say it, tell them in person, or use a different app. Never put it in the same thread as the link.
The last step is where most people slip. Our guide to sending the passcode safely covers which second channels work best.
What should the text message actually say?
People are rightly wary of links in texts. A clear, personal message stops your recipient from deleting it as a scam and tells them how the link behaves.
A small business owner sending a new employee their till login might write:
Hi Sam, it's Priya from the shop. Your till login is in this link. It opens once and expires tomorrow, so open it when you're standing at the till. I'll tell you the code when you come in.
Someone helping a parent with the home Wi-Fi might write:
Hi Mum, the Wi-Fi password is in this link. It only works once. I'll ring you in a minute with the code to open it.
Notice what's missing: the passcode, and any detail that tells a stranger what the password unlocks. If the link leaks, the text alone gives nothing away.
If you've never sent a text with a link to this person before, warn them first by call or in person. That habit also protects them from scammers who imitate this exact kind of message.
Which way of sharing a password by phone is safest?
Texting a one-time link isn't the only option. Here's how the common choices compare for a typical password handover.
| Option | Encrypted end-to-end? | Leaves a lasting copy? | Best for |
|---|---|---|---|
| Plain SMS with the password | No | Yes: both phones, synced devices, backups, possibly the carrier | Nothing sensitive |
| iMessage, WhatsApp or Signal with the password | Yes, in transit | Yes: chat history on both phones and possibly backups, unless disappearing messages are on | Low-stakes passwords between people who already use the app |
| Text message with a one-time link | The link travels by SMS; the note is encrypted when stored | No: the link stops working after it's viewed or expires | One-off passwords to anyone with a phone |
| Phone call | Not applicable | No written copy | Short codes, door codes, passcodes |
| Password manager sharing | Depends on the product | Yes, on purpose, in a protected vault | Passwords shared on an ongoing basis |
A phone call is fine for something short, like a four-digit door code from a landlord. It gets painful for a 16-character password with symbols, and the listener often writes it on a sticky note.
If your family or team shares the same logins month after month, a one-time link is the wrong tool. A password manager with sharing built in keeps everyone in sync. Our comparison of one-time links and password vaults explains where each fits.
What can still go wrong when you text a password safely?
A one-time link removes the biggest risk, but people still trip up in predictable ways.
- Passcode in the same thread. Sending the link and then texting the code a minute later puts both halves in one place. Anyone who sees the thread has everything.
- Generous settings. Ten views and 30 days turns a one-time link into a long-lived one. Use 1 view and the shortest time limit that fits the situation.
- Too much context. A text that says which bank, email address or business account the link unlocks helps an attacker more than it helps your recipient.
- The password gets copied somewhere else. If the recipient screenshots the note or pastes the password into their notes app, it now lives on their phone and in their backups. Ask them to type it straight into the login screen or their password manager.
- Links opened automatically. Some messaging apps, work phones and security scanners open links to build previews or check for threats. If your recipient finds the link already used, assume someone saw it, send a fresh note and change the password.
- Wrong number. Phone numbers get recycled and contacts get mixed up. Double-check before you hit send.
- Falling for a fake request. If a text from a family member or colleague asks you to send a password, call them on a number you already have before you do anything.
Also remember what a one-time link can't do. It protects the handover, not the device. If the recipient's phone is already compromised, or they reuse the password everywhere, the link won't fix that. The same logic applies to other channels, which is why we also recommend links when you email a password securely.
What to do if you already texted the password
It happens. Someone needed the login in a hurry and you typed it into a text. Here's how to clean up.
- Change the password. This is the only step that actually closes the gap, because you can't delete every copy of the text.
- Change it anywhere else you've reused it. If the same password protects other accounts, those are exposed too.
- Turn on two-step verification for the account, ideally with an authenticator app rather than SMS codes.
- Check recent activity. Look for unfamiliar sign-ins, devices or changes to recovery email and phone settings.
- Delete the text on both phones. It won't touch backups or carrier records, but it removes the copy from lock screens and casual snooping.
- Send the new password the safe way. Send a secure note with a one-time link and share the passcode by phone.
Don't panic about a low-stakes password, like a guest Wi-Fi network, that's already been texted. Do act quickly on anything tied to money, email or a work account, since email access often lets someone reset everything else.
Frequently asked questions
Can my phone carrier see my text messages?
Standard SMS isn't end-to-end encrypted, so carriers handle message content in readable form while routing it, and some keep records for periods set by their own policies and local law. Rather than guessing who keeps what, assume a plain text may be stored somewhere you can't delete it, and keep passwords out of it entirely.
Are iMessage, WhatsApp or Signal safe for sending passwords?
They're safer than plain SMS because messages are end-to-end encrypted in transit. But the password still sits in chat history on both phones, on any linked computers, and possibly in backups. Turning on disappearing messages helps. Sending a one-time link through these apps is better still, because the password itself never enters the chat.
Is it OK to text a Wi-Fi password?
For a guest network at home, it's a modest risk, since someone would need to be within range to use it. For your main network or a business network, send a one-time link instead, or share it in person using your phone's Wi-Fi QR code option. If the password has been texted to lots of people over time, change it.
Should I ever text someone a verification code I received?
No. A one-time code sent to your phone by a bank, email provider or app is meant only for you. Scammers often pose as friends, delivery firms or support staff and ask you to forward the code so they can take over your account. If anyone asks for a code you received, stop and call them on a number you trust.
Does deleting a text remove it everywhere?
No. Deleting removes the message from that device, and sometimes from devices synced to the same account. It doesn't reach the other person's phone, older backups or anything the carrier keeps. That's why the right response to a texted password is to change the password, not just delete the message.
Can someone intercept a link sent by text?
The link travels over SMS like any other text, so someone with access to the thread could see it. That's why you set the note to 1 view, a short time limit and a passcode sent separately. If someone else opens it first, your recipient finds a dead link, which is your signal to change the password.